CVE-2026-32711: 
Python vulnerability analysis and mitigation

Overview

CVE-2026-32711 is a path traversal vulnerability in pydicom, a pure Python package for working with DICOM medical imaging files. It affects versions 2.0.0-rc.1 through 3.0.1 (including all 2.x releases prior to 2.4.5 and 3.x releases prior to 3.0.2), and was disclosed on March 20, 2026. The flaw allows a maliciously crafted DICOMDIR file with a ReferencedFileID set to a path outside the File-set root to enable arbitrary file read, copy, move, or delete operations on the host system. It carries a CVSS v3.1 base score of 7.8 (High) (Github Advisory, pydicom Security Advisory).

Technical details

The root cause is CWE-22 (Improper Limitation of a Pathname to a Restricted Directory), located in src/pydicom/fileset.py. The vulnerable RecordNode._file_id method converts the ReferencedFileID DICOM attribute directly to a Path object without verifying that the resolved path remains within the File-set root directory — it only checks that the path exists via resolve(strict=True), not that it is contained under the root. As a result, FileSet operations including copy(), write(), and remove()+write(use_existing=True) pass the unchecked path to shutil.copyfile, shutil.move, and Path.unlink, enabling traversal via absolute paths (e.g., /etc/passwd), relative traversal sequences (../...), or symlink-based escapes using syntactically conformant file IDs. The fix in version 3.0.2 adds a containment check using resolved.is_relative_to(root) and raises a PermissionError for out-of-bounds paths (pydicom Security Advisory, Security Fix Commit).

Impact

Successful exploitation allows an attacker to read, copy, move, or delete arbitrary files accessible to the process running pydicom, outside the intended File-set root directory. The most realistic server-side scenario involves a user uploading a malicious DICOM File-set archive; when the server loads and re-exports it using FileSet.copy() or FileSet.write(), sensitive server-local files (e.g., /etc/passwd, credentials, configuration files) can be exfiltrated in the exported result. In destructive flows using remove()+write(use_existing=True), files outside the File-set root can be deleted, posing an availability risk. All three CIA pillars are affected: confidentiality (file disclosure), integrity (file modification/move), and availability (file deletion) (pydicom Security Advisory, Github Advisory).

Exploitability

A complete, runnable proof-of-concept Python script is publicly available in the pydicom security advisory, demonstrating the vulnerability by modifying a DICOMDIR file's ReferencedFileID to /etc/passwd and calling FileSet.copy() to extract the file (pydicom Security Advisory). As of the time of reporting, there is no evidence of active in-the-wild exploitation, and no threat actor attribution has been made. The EPSS score is approximately 0.016% (1st percentile), indicating a low current probability of exploitation (Github Advisory). The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Exploitation requires user interaction — specifically, a user or server process must open a maliciously crafted DICOMDIR file.

Exploitation steps

  1. Craft a malicious DICOMDIR: Start with a valid DICOM File-set containing a DICOMDIR file. Modify one DirectoryRecordSequence item so that ReferencedFileID is set to a target path outside the File-set root, such as /etc/passwd or ../../../etc/shadow.
  2. Package and deliver: Bundle the malicious DICOMDIR and associated DICOM files into a zip archive or directory structure. Deliver it to a target system — for example, by uploading it to a server that accepts DICOM File-set imports.
  3. Trigger FileSet loading: The target application (or a user) loads the DICOMDIR using FileSet(ds) or FileSet(path_to_dicomdir). pydicom resolves the malicious path and confirms it exists, but does not verify containment within the File-set root.
  4. Trigger file I/O operation: Cause the application to call FileSet.copy(output_dir), FileSet.write(), or FileSet.remove()+write(use_existing=True). pydicom passes the unvalidated path to shutil.copyfile, shutil.move, or Path.unlink.
  5. Exfiltrate or destroy target file: In the copy() flow, the referenced external file (e.g., /etc/passwd) is copied into the exported File-set output directory, where the attacker can retrieve it. In the write() or remove()+write() flow, the file may be moved or deleted from the server (pydicom Security Advisory, Github Advisory).

Indicators of compromise

  • File System: Unexpected files from outside the DICOM File-set root (e.g., /etc/passwd, configuration files, credential files) appearing in DICOM export or output directories; missing or moved system files in cases of destructive exploitation.
  • Logs: Application logs showing FileSet.copy(), FileSet.write(), or FileSet.remove() operations on paths outside the expected DICOM data directory; pydicom warning messages about invalid ReferencedFileID values in DICOMDIR processing logs.
  • File System: Uploaded DICOMDIR files containing ReferencedFileID values with absolute paths (e.g., starting with /) or path traversal sequences (e.g., ../) in the DirectoryRecordSequence.
  • Network: Unusual outbound transfers of files with content matching system files (e.g., /etc/passwd format) from DICOM import/export endpoints (pydicom Security Advisory).

Mitigation and workarounds

The primary remediation is to upgrade pydicom to version 3.0.2 or 2.4.5 (for users on the 2.x branch), both of which include the security fix (pydicom Release v3.0.2, Security Fix Commit). As a workaround prior to patching, restrict acceptance of DICOMDIR files to trusted sources only, and avoid processing untrusted DICOM File-sets with FileSet.copy(), FileSet.write(), or FileSet.remove(). Additionally, implement file integrity monitoring on sensitive directories and run DICOM processing services with least-privilege accounts to limit the impact of exploitation (Github Advisory).

Community reactions

The vulnerability was reported by security researcher jh4nks and published by pydicom maintainer darcymason on March 20, 2026. The fix was merged promptly as a patch release (3.0.2), with the release notes explicitly referencing CVE-2026-32711. OpenSUSE issued security announcements for the affected package, and Fedora also released updates. Tenable published multiple Nessus detection plugins (IDs 303276, 305676, 305672, 310689) for the vulnerability (pydicom Security Advisory, pydicom Release v3.0.2).

Additional resources

Linux Distribution fix status

Fix availability across major Linux distributions and their releases.

Debian

Fixed

bookworm

pydicom

Affected

sid

pydicom: 3.0.2-1

Fixed

trixie

pydicom

Affected

Ubuntu

Unknown

bionic (esm-apps)

pydicom

Unknown

devel

pydicom

Unknown

focal (esm-apps)

pydicom

Unknown

jammy

pydicom

Unknown

jammy (esm-apps)

pydicom

Unknown

noble

pydicom

Unknown

noble (esm-apps)

pydicom

Unknown

resolute

pydicom

Unknown

Alpine

Fixed

edge

py3-pydicom: 3.0.2-r0

Fixed

v3.23

py3-pydicom: 3.0.2-r0

Fixed

Source: This report was generated using AI

Related Python vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

GHSA-v2f8-6655-7grjCRITICAL10
  • Python logoPython
  • vibe-trading-ai
NoYesOct 02, 2026
CVE-2026-105782HIGH7.5
  • Python logoPython
  • scrapy
NoYesOct 06, 2026
GHSA-v853-p72q-4cfwHIGH7.5
  • Python logoPython
  • quart
NoYesOct 05, 2026
CVE-2026-105751MEDIUM6.9
  • Python logoPython
  • docling
NoYesOct 05, 2026
CVE-2026-105750MEDIUM5.9
  • Python logoPython
  • docling
NoYesOct 05, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management